CVE-2010-0806
Microsoft Internet Explorer Use-After-Free Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 June 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 82.17% probability · 100th percentile
- CISA KEV
- Listed 20 May 2026 · due 3 June 2026
- Weakness
- CWE-399, CWE-416
- Affected
- microsoft/internet explorer
- Source
- secure@microsoft.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://learn.microsoft.com/en-us/security-updates/securityadvisories/2010/981374 ; https://nvd.nist.gov/vuln/detail/CVE-2010-0806
References
- http://blogs.technet.com/msrc/archive/2010/03/09/security-advisory-981374-released.aspxBroken Link
- http://osvdb.org/62810Broken Link
- http://secunia.com/advisories/38860Vendor Advisory
- http://www.kb.cert.org/vuls/id/744549Patch, US Government Resource
- http://www.microsoft.com/technet/security/advisory/981374.mspxBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/38615Broken Link
- http://www.us-cert.gov/cas/techalerts/TA10-068A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA10-089A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2010/0567Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0744Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-018Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56772Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8446Broken Link
- http://blogs.technet.com/msrc/archive/2010/03/09/security-advisory-981374-released.aspxBroken Link
- http://osvdb.org/62810Broken Link
- http://secunia.com/advisories/38860Vendor Advisory
- http://www.kb.cert.org/vuls/id/744549Patch, US Government Resource
- http://www.microsoft.com/technet/security/advisory/981374.mspxBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/38615Broken Link
- http://www.us-cert.gov/cas/techalerts/TA10-068A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA10-089A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2010/0567Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0744Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-018Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56772Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8446Broken Link
- https://learn.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-018Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0806US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.